Core
Cyber Threat Intelligence
Cyber threat intelligence earns its place only when someone acts differently because of it. This course builds the capability end to end: requirements, collection, analysis, and reporting that a decision maker can use.
You practise structured analytic techniques, track adversaries by behaviour using MITRE ATT&CK, and write products for operational and executive readers, ending with a full intelligence assessment on an active threat.
- Duration
- 8 weeks
- Format
- Live online, instructor-led
- Prerequisites
- None required
- Class size
- Capped at 12 learners

What you will be able to do
- Write intelligence requirements tied to decisions someone actually makes
- Build a collection plan across internal telemetry and external sources
- Grade source reliability and information credibility consistently
- Apply analysis of competing hypotheses to a real ambiguous case
- Track adversary behaviour with MITRE ATT&CK rather than indicator lists
- State attribution claims at a level the evidence supports
- Convert reporting into detections, hunts and priorities
- Brief an executive audience using estimative language correctly
Course outline
6 modules
- Intelligence requirements and who they serve
- Strategic, operational and tactical products
- The intelligence cycle applied to a small team
- Common failure modes in intelligence programmes
- Measuring whether intelligence changed anything
What you need before you start
- General security knowledge and familiarity with common attack patterns
- Confident written English, since much of the work is writing
- No programming required, though basic scripting helps with collection
- Time each week to complete analytic exercises before class
Who this course is for
- Analysts starting or running a threat intelligence function
- SOC and hunting staff who consume intelligence and want better inputs
- Incident responders who produce intelligence as a by-product of casework
- Risk and security managers who commission intelligence reporting
- Consultants writing threat assessments for clients
Questions about this course
More in digital forensics and incident response
Ready to launch your cyber security career?
Join the next live online cohort. No experience required, just bring the curiosity.



